Skip to content
TECH CEO Daily

Device code phishing kits beat MFA at thousands of firms, from EvilTokens to GhostCode

Three September disclosures show phishing kits stealing sign-in tokens, with EvilTokens rented by subscription and adding AI inbox analysis. Standard multifactor prompts no longer stop them.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Microsoft says EvilTokens has been linked to more than 12,000 compromised inboxes at over 10,000 organizations since its February 2026 launch.
  • 2eSentire found the GhostCode kit obtained a powerful Microsoft sign-in token 32 seconds after a victim authenticated.
  • 3CloudSEK says BigBear bypassed MFA at 258 organizations. Security keys and passkeys counter proxy kits like it, but device code phishing runs on Microsoft's real sign-in page, so eSentire and Microsoft advise blocking that flow where it isn't needed.

The news

Device code phishing and other token-theft kits have been linked to account compromises at thousands of organizations in 2026 despite multifactor authentication (MFA), according to research published in September by Microsoft, eSentire and CloudSEK. The kits capture the sign-in tokens issued after MFA succeeds, so passwords alone are not what attackers need.

The largest case is EvilTokens. On September 22, Microsoft (MSFT) said its Digital Crimes Unit had obtained a court order in the U.S. District Court for the Eastern District of Virginia to seize 50 websites and disable more than 150 supporting domains. Microsoft said the service, launched in February 2026, had been linked to more than 12,000 compromised email inboxes at over 10,000 organizations, and was sold on Telegram for a $1,500 setup fee plus a $500 monthly subscription. Microsoft said the Metropolitan Police arrested two men, aged 32 and 38, in the U.K. on September 11 on suspicion of offenses linked to allegedly running EvilTokens; both were released on police bail, with no charges reported.

EvilTokens relied on device code phishing, which abuses the OAuth 2.0 device authorization grant, a legitimate sign-in standard for input-limited devices such as smart TVs. Victims enter a code on the real Microsoft login page, complete MFA, and unknowingly grant the attacker access. Microsoft said the service's AI chatbot could then analyze a victim's inbox to spot trusted relationships and payment authorizations and suggest fraud strategies.

eSentire's September 15 analysis of a separate kit, GhostCode, shows the speed involved. Attackers posed as procurement officers, sent password-protected files through WeTransfer, and steered victims to a device code prompt. After the victim signed in, the attackers began enrolling devices in Microsoft Intune within five seconds, obtained a Primary Refresh Token within 32 seconds, and had three devices registered within 78 seconds. eSentire said such tokens enable single sign-on across a tenant and persist for up to 14 days.

A third service used a different route to the same result. CloudSEK, which gained access to the BigBear 2.0 control panel, found completed MFA bypasses at 258 organizations and more than 5,000 stolen credential records, BleepingComputer reported on September 7. BigBear used an adversary-in-the-middle proxy that relays the real login page, and custom code that disabled FIDO2 security key sign-in to force weaker methods.

The numbers

Compromised inboxes linked to EvilTokens
12,000+
Organizations linked to EvilTokens compromises
10,000+
EvilTokens price
$1,500 setup + $500/month
GhostCode time to Primary Refresh Token
32 seconds
Organizations with BigBear MFA bypass
258

Why CEOs should care

For CISOs, the fixes are specific. eSentire, like Microsoft's security researchers, recommends blocking the device code sign-in flow through Conditional Access for everyone except the few users and devices that genuinely need it. eSentire also advises requiring managed, compliant devices for access, and alerting when one session registers several devices. CloudSEK's advice after BigBear is to revoke sessions and refresh tokens, not just reset passwords, and to enforce FIDO2 or WebAuthn security keys and passkeys, which bind sign-in to the real website and defeat proxy pages.

For CFOs and controllers, the EvilTokens chatbot was built to find payment workflows inside stolen mailboxes. Microsoft advises checking any request to alter payment details or make an unusual transfer through a second, trusted means of contact. Make that a written control with named owners, and test it with finance staff and key suppliers.

For boards, ask two questions: what share of employees can still sign in with methods that a phishing kit can relay, and how quickly can the security team revoke every token for a compromised account? If the answers are unclear, identity should be on the next audit committee agenda.

The bigger picture

The pattern is commercialization. Subscription pricing, affiliate operators and AI features turn token theft into a service that low-skill criminals can rent. Against proxy kits, Google Threat Intelligence Group's August report on the extortion group UNC6671, which paired phone-based social engineering with adversary-in-the-middle pages, recommends phishing-resistant authenticators, which work only on the genuine website. That does not stop device code phishing, where victims sign in on Microsoft's own page.

The targets matter too. Microsoft listed wholesale distribution, construction, financial services, real estate, higher education and healthcare among the sectors EvilTokens targeted, and GhostCode's operators posed as buyers approaching sales teams. These are businesses that move money and sign deals on the strength of email, which is exactly where a hijacked inbox pays off.

What’s next

Expect more takedowns like Microsoft's, which it called its 40th court-authorized disruption, and more kits that target whatever sign-in flows remain open. Watch Microsoft's default policies for device code authentication, and whether cyber insurers begin asking about phishing-resistant MFA coverage at renewal.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

MicrosoftEvilTokensPhishingIdentity security

Earlier coverage of Microsoft

All Microsoft coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.